Database/Kernel, userspace & hypervisor
Linux kernel (drivers/nvme/target): Every command a client sends to the target carrying metadata (protection
Impact
Every command a client sends to the target carrying metadata (protection information) leaks the bio integrity payload permanently. A tenant or peer issuing metadata-bearing I/O in a loop grows kernel slab without bound until the shared storage node runs out of memory.
Who can reach it
Driven entirely by a connected NVMe-oF client's command stream against an exported namespace - the leak is on the normal inline-bio path, not an error path, so no crafted failure is needed. Any peer allowed to connect to the subsystem can drive it. Conditional on the exported namespace supporting metadata/PI, which is the case for formatted-with-PI backing devices.
What to do
Update to 6.11 or later (or a stable branch carrying the linked commits). Interim: export namespaces without protection information where the workload permits, and alert on unexplained kmalloc-128 slab growth on target nodes.
References
Related entries
- Linux kernel (drivers/nvme/target): Ordinary client I/O to an nvmet block-device namespace can hit a completion raceCVE-2026-23148 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): A client that completes the TLS handshake against the NVMe-oF TCP target and thenCVE-2026-74385 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): Every connection that dies partway through queue allocation on the NVMe-oF TCPCVE-2026-74386 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): A client that asks the target to create a submission queue with an invalid queue IDCVE-2026-72128 · Linux kernel (drivers/nvme/target)Medium
- Linux kernel (drivers/nvme/target): The target disables a namespace without waiting for in-flight I/O to drain, so aCVE-2025-21850 · Linux kernel (drivers/nvme/target)Critical
- Linux kernel (drivers/nvme/target): A client connected to your NVMe-oF TCP target can drive a reference-count underflowCVE-2026-64534 · Linux kernel (drivers/nvme/target)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.